From 64f0bd1e8f6d4a02aca5ff87494e661e99dd4505 Mon Sep 17 00:00:00 2001 From: AzenKain Date: Wed, 2 Sep 2026 13:14:41 +0700 Subject: [PATCH] feat: enhance proxy functionality with verbose logging and support for additional Linux distributions --- cache.go | 6 +++++- cert_linux.go | 28 ++++++++++++++++++++++++++ go.mod | 8 ++++---- go.sum | 12 +++++------ main.go | 46 +++++++++++++++++++++++++++++-------------- script/README_Note.md | 3 ++- script/release.json | 4 ++-- system_proxy_linux.go | 21 ++++++++------------ 8 files changed, 86 insertions(+), 42 deletions(-) diff --git a/cache.go b/cache.go index 8cc76d2..8cff8c9 100644 --- a/cache.go +++ b/cache.go @@ -24,7 +24,11 @@ func (cs *CertStorage) Fetch(hostname string, gen func() (*tls.Certificate, erro } cs.mtx.Lock() - cs.certs[hostname] = cert + if existing, ok := cs.certs[hostname]; ok { + cert = existing + } else { + cs.certs[hostname] = cert + } cs.mtx.Unlock() return cert, nil diff --git a/cert_linux.go b/cert_linux.go index 1566641..95c6824 100644 --- a/cert_linux.go +++ b/cert_linux.go @@ -58,5 +58,33 @@ func installCA(absPath string) error { return cmd.Run() } + // Fedora / RHEL / CentOS / Rocky / AlmaLinux + if strings.Contains(content, "ID=fedora") || + strings.Contains(content, "ID=rhel") || + strings.Contains(content, "ID=centos") || + strings.Contains(content, "ID=rocky") || + strings.Contains(content, "ID=almalinux") { + + destDir := "/etc/pki/ca-trust/source/anchors" + if err := os.MkdirAll(destDir, 0755); err != nil { + return fmt.Errorf("failed to create cert dir: %v", err) + } + + destPath := filepath.Join(destDir, filepath.Base(absPath)) + + inputData, err := os.ReadFile(absPath) + if err != nil { + return fmt.Errorf("failed to read source file: %v", err) + } + if err := os.WriteFile(destPath, inputData, 0644); err != nil { + return fmt.Errorf("failed to write cert file to system: %v", err) + } + + cmd := exec.Command("update-ca-trust") + cmd.Stdout = os.Stdout + cmd.Stderr = os.Stderr + return cmd.Run() + } + return fmt.Errorf("unsupported Linux distribution") } diff --git a/go.mod b/go.mod index 996abfb..9d93552 100644 --- a/go.mod +++ b/go.mod @@ -1,9 +1,9 @@ module firefly-go-proxy -go 1.26.1 +go 1.27.0 require ( - github.com/elazarl/goproxy v1.8.5 + github.com/elazarl/goproxy v1.9.0 github.com/rs/zerolog v1.35.1 golang.org/x/sys v0.47.0 ) @@ -11,6 +11,6 @@ require ( require ( github.com/mattn/go-colorable v0.1.15 // indirect github.com/mattn/go-isatty v0.0.24 // indirect - golang.org/x/net v0.57.0 // indirect - golang.org/x/text v0.40.0 // indirect + golang.org/x/net v0.58.0 // indirect + golang.org/x/text v0.41.0 // indirect ) diff --git a/go.sum b/go.sum index da5d054..3ba3c85 100644 --- a/go.sum +++ b/go.sum @@ -2,8 +2,8 @@ github.com/coder/websocket v1.8.14 h1:9L0p0iKiNOibykf283eHkKUHHrpG7f65OE3BhhO7v9 github.com/coder/websocket v1.8.14/go.mod h1:NX3SzP+inril6yawo5CQXx8+fk145lPDC6pumgx0mVg= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= -github.com/elazarl/goproxy v1.8.5 h1:33R3Q6geBd2PHmjEI82s3dQWSoBKjTktg4YAFXutIoY= -github.com/elazarl/goproxy v1.8.5/go.mod h1:b5xm6W48AUHNpRTCvlnd0YVh+JafCCtsLsJZvvNTz+E= +github.com/elazarl/goproxy v1.9.0 h1:2j3c13lD5v0QTjxphJSSIHS7w8/m/pzSHtLMPOpznC0= +github.com/elazarl/goproxy v1.9.0/go.mod h1:THdE5ix2clxX9lZzcICPpZ67d6CdrPZxdOYsNgU5e30= github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY= github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI= @@ -14,11 +14,11 @@ github.com/rs/zerolog v1.35.1 h1:m7xQeoiLIiV0BCEY4Hs+j2NG4Gp2o2KPKmhnnLiazKI= github.com/rs/zerolog v1.35.1/go.mod h1:EjML9kdfa/RMA7h/6z6pYmq1ykOuA8/mjWaEvGI+jcw= github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= -golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= -golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= +golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= +golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU= golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= -golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs= -golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY= +golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= +golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= diff --git a/main.go b/main.go index aae3883..4136445 100644 --- a/main.go +++ b/main.go @@ -50,6 +50,7 @@ func main() { exePath := flag.String("e", "", "path to the executable") parentPID := flag.Int("parent-pid", 0, "parent process id to watch") noSys := flag.Bool("no-sys", false, "skip certificate installation and system proxy setup") + verbose := flag.Bool("v", false, "log every request (PASS/redirect)") flag.Parse() redirectScheme, redirectTarget := parseRedirect(*redirectHost) @@ -132,7 +133,8 @@ func main() { MaxIdleConnsPerHost: 100, IdleConnTimeout: 90 * time.Second, DisableCompression: false, - TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, + ForceAttemptHTTP2: true, + TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, } proxy.CertStore = NewCertStorage() proxy.OnRequest().HandleConnect(customAlwaysMitm) @@ -146,12 +148,16 @@ func main() { } if matchDomain(host, AlwaysIgnoreDomains) { - zlog.Warn().Str("url", req.URL.String()).Msg("PASS URL") + if *verbose { + zlog.Warn().Str("url", req.URL.String()).Msg("PASS URL") + } return req, nil } if matchURL(path, AlwaysIgnoreUrls) { - zlog.Warn().Str("url", req.URL.String()).Msg("PASS URL") + if *verbose { + zlog.Warn().Str("url", req.URL.String()).Msg("PASS URL") + } return req, nil } @@ -180,35 +186,45 @@ func main() { full := req.URL.String() if containsURL(full, ForceRedirectOnUrlContains) { - zlog.Info(). - Str("from_url", full). - Str("raw_query", rawQuery). - Msg("Force redirect") + if *verbose { + zlog.Info(). + Str("from_url", full). + Str("raw_query", rawQuery). + Msg("Force redirect") + } req.URL.Scheme = redirectScheme req.URL.Host = redirectTarget req.Host = redirectTarget req.URL.RawQuery = rawQuery req.RequestURI = "" - zlog.Info().Str("to_url", req.URL.String()).Msg("Force redirected") + if *verbose { + zlog.Info().Str("to_url", req.URL.String()).Msg("Force redirected") + } return req, nil } - zlog.Info(). - Str("host", host). - Str("from_url", full). - Str("raw_query", rawQuery). - Msg("Redirect domain") + if *verbose { + zlog.Info(). + Str("host", host). + Str("from_url", full). + Str("raw_query", rawQuery). + Msg("Redirect domain") + } req.URL.Scheme = redirectScheme req.URL.Host = redirectTarget req.Host = redirectTarget req.URL.RawQuery = rawQuery req.RequestURI = "" - zlog.Info().Str("to_url", req.URL.String()).Msg("Redirected domain") + if *verbose { + zlog.Info().Str("to_url", req.URL.String()).Msg("Redirected domain") + } return req, nil } - zlog.Warn().Str("url", req.URL.String()).Msg("PASS URL") + if *verbose { + zlog.Warn().Str("url", req.URL.String()).Msg("PASS URL") + } return req, nil }) diff --git a/script/README_Note.md b/script/README_Note.md index 9c3a84d..e4ef7ef 100644 --- a/script/README_Note.md +++ b/script/README_Note.md @@ -1,4 +1,5 @@ # Changelog ### UPDATE -- Support linux, macos, window \ No newline at end of file + +- Optimize proxy diff --git a/script/release.json b/script/release.json index 00b6d4b..abefad4 100644 --- a/script/release.json +++ b/script/release.json @@ -1,5 +1,5 @@ { - "tag": "1.4-02", - "title": "PreBuild Version 1.4 - 02" + "tag": "1.4-03", + "title": "PreBuild Version 1.4 - 03" } \ No newline at end of file diff --git a/system_proxy_linux.go b/system_proxy_linux.go index e2e5d4e..fb37274 100644 --- a/system_proxy_linux.go +++ b/system_proxy_linux.go @@ -3,21 +3,16 @@ package main -import "fmt" - func setProxy(enable bool, host string, port string) error { - - httpProxy1 := fmt.Sprintf("HTTP_PROXY=http://%s:%s", host, port) - httpProxy2 := fmt.Sprintf("http_proxy=http://%s:%s", host, port) - - ENV_CONFIG = append(ENV_CONFIG, httpProxy1, httpProxy2) - - httpsProxy1 := fmt.Sprintf("HTTPS_PROXY=http://%s:%s", host, port) - httpsProxy2 := fmt.Sprintf("https_proxy=http://%s:%s", host, port) - ENV_CONFIG = append(ENV_CONFIG, httpsProxy1, httpsProxy2) - if enable { - ENV_CONFIG = make([]string, 0) + ENV_CONFIG = []string{ + "HTTP_PROXY=http://" + host + ":" + port, + "http_proxy=http://" + host + ":" + port, + "HTTPS_PROXY=http://" + host + ":" + port, + "https_proxy=http://" + host + ":" + port, + } + } else { + ENV_CONFIG = nil } return nil